
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the comment.
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Comment .
The attacker must post something on the "comment" and insert the XSS payload at the "comment" input, and pick the Raw HTML Editor in order to exploit the stored XSS. The XSS payload will be launched immediately after save.
http://ip_address/backdrop/comment/reply/id_reply
POST /backdrop/comment/reply/id_reply
Backdrop CMS version 1.23.0 (https://github.com/backdrop/backdrop/releases/tag/1.23.0)
Firefox version 105
:shipit: Grim The Ripper Team by SOSECURE Thailand
Reference: